CVE-2023-46273

8.8

Extreme Networks · IQ Engine

Extreme Networks IQ Engine contains a stack-based buffer overflow in the Bonjour Gateway, which can be triggered via the ah_event_send function to potentially execute arbitrary code.

Executive summary

A critical stack-based buffer overflow in the Extreme Networks IQ Engine allows authenticated attackers to execute arbitrary code.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) within the Bonjour Gateway component. It can be triggered via the ah_event_send function, specifically impacting the ah_auth service, and is reachable through the ah_webui service listening on TCP port 3009.

Business impact

Successful exploitation of this vulnerability could allow an attacker with low privileges to execute arbitrary code on the affected IQ Engine. Given the CVSS score of 8.8, this poses a high risk to system integrity and availability, potentially leading to a full compromise of the networking device and unauthorized access to the underlying management infrastructure.

Remediation

Immediate Action: Upgrade Extreme Networks IQ Engine to version 10.6r1a or 10.6r5 immediately to patch the buffer overflow.

Proactive Monitoring: Monitor network traffic directed at TCP port 3009 for anomalous patterns or unexpected service interactions that may indicate exploitation attempts.

Compensating Controls: Restrict access to the ah_webui management interface to trusted administrative IP addresses using network ACLs or firewall rules to minimize exposure.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this flaw, combined with the potential for remote code execution, necessitates immediate patching. Organizations should prioritize updating their IQ Engine firmware to the remediated versions to eliminate this critical security risk.

More Extreme Networks CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources